[ubuntu/precise-updates] subversion 1.6.17dfsg-3ubuntu3.8 (Accepted)

Ubuntu Archive Robot ubuntu-archive-robot at lists.canonical.com
Mon May 3 14:32:55 UTC 2021


subversion (1.6.17dfsg-3ubuntu3.8) precise-security; urgency=medium

  * SECURITY UPDATE: Remotely triggerable DoS vulnerability in svnserve
    'get-deleted-rev' and Remote unauthenticated denial-of-service
    - debian/patches/CVE-2018-11782-and-CVE-2019-0203.patch: properly handle certain replies
      in subversion/libsvn_ra_svn/client.c, subversion/svnserve/serve.c,
    - CVE-2018-11782
    - CVE-2019-0203

subversion (1.6.17dfsg-3ubuntu3.7) precise-security; urgency=medium

  * SECURITY UPDATE: Arbitrary code execution on clients through
    malicious svn+ssh URLs
    - debian/patches/CVE-2017-9800.patch: ensure that host
      arguments to ssh cannot be treated as ssh options.
    - CVE-2017-9800
  * SECURITY UPDATE: svnserve/sasl may authenticate users using the
    wrong realm.
    - debian/patches/CVE-2016-2167.patch: Reject invalid usernames when
      SASL is being used.
    - CVE-2016-2167
  * SECURITY UPDATE: remotely triggerable crash in the mod_authz_svn
    module.
    - debian/patches/CVE-2016-2168.patch: Reject requests with invalid
      Destination headers.
    - CVE-2016-2168

Date: 2019-07-29 18:25:19.601062+00:00
Changed-By: leo.barbosa at canonical.com (Leonidas S. Barbosa)
Signed-By: Ubuntu Archive Robot <ubuntu-archive-robot at lists.canonical.com>
https://launchpad.net/ubuntu/+source/subversion/1.6.17dfsg-3ubuntu3.8
-------------- next part --------------
Sorry, changesfile not available.


More information about the Precise-changes mailing list